The vulnerability exists due to failure in the "/admin/admin.php" script to properly sanitize user-supplied input in "page_menu" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

An attacker can use browser to exploit this vulnerability. The following PoC is available: